nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-3591 CVE-2024-3591
MEDIUM
WordPress Geo Controller < 8.6.5 - PHP Object Injection
Record summary
CVE-2024-3591 has a selected CVSS score of 6.5 (medium).
Description
The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Geo ControllerDefault status: unaffected | CVE List | Before 8.6.5 | affected |
geo_controllerBrowse wordpress / geo_controllerDefault status: unknown | CVE List | - to < 8.6.5 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/f85d8b61-eaeb-433c-b857-06ee4db5c7d5